312-50V10 · Question #831
Bobby, an attacker, targeted a user and decided to hijack and intercept all their wireless communications. He installed a fake communication tower between two authentic endpoints to mislead the victim
The correct answer is B. KRACK attack. This question tests recognition of wireless man-in-the-middle attacks that use rogue access points to intercept and redirect victim traffic.
Question
Bobby, an attacker, targeted a user and decided to hijack and intercept all their wireless communications. He installed a fake communication tower between two authentic endpoints to mislead the victim. Bobby used this virtual tower to interrupt the data transmission between the user and real tower, attempting to hijack an active session, upon receiving the users request. Bobby manipulated the traffic with the virtual tower and redirected the victim to a malicious website. What is the attack performed by Bobby in the above scenario?
Options
- AWardriving
- BKRACK attack
- Cjamming signal attack
- DaLTEr attack
How the community answered
(35 responses)- A14% (5)
- B77% (27)
- C6% (2)
- D3% (1)
Why each option
This question tests recognition of wireless man-in-the-middle attacks that use rogue access points to intercept and redirect victim traffic.
Wardriving is the passive act of scanning for wireless networks while moving through an area, and does not involve actively intercepting or hijacking sessions.
KRACK (Key Reinstallation Attack) exploits the WPA2 four-way handshake by forcing nonce reuse, enabling an attacker to position a rogue access point between the victim and a legitimate wireless tower to intercept, decrypt, and manipulate traffic. This allows the attacker to hijack active sessions and redirect users to malicious websites. The fake communication tower in this scenario represents the rogue AP used to perform the man-in-the-middle interception.
A jamming signal attack floods the wireless spectrum with interference to cause a denial of service, but does not allow the attacker to intercept, manipulate, or redirect communications.
The aLTEr attack specifically targets LTE cellular network protocols by exploiting missing integrity protection at the data link layer, which is a distinct vulnerability from the WPA2 handshake flaw exploited in the described scenario.
Concept tested: KRACK wireless man-in-the-middle session hijacking
Source: https://www.krackattacks.com/
Topics
Community Discussion
No community discussion yet for this question.